Australian law
How the Privacy Act 1988 applies when your team member is in the Philippines
The Privacy Act 1988 covers most Australian businesses with annual turnover above A$3 million, plus some smaller ones such as health service providers. If it covers you, three parts of it matter when you engage offshore staff.
APP 8, cross-border disclosure
Before you disclose personal information to an overseas recipient, APP 8 requires you to take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles. The Office of the Australian Information Commissioner (OAIC) says that giving personal information to an overseas contractor is a disclosure in most circumstances, and that the reasonable step is usually an enforceable contract. Under section 16C of the Act, you remain accountable for what the overseas recipient does with the information.
APP 11, security
You must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. Since the 2024 amendments, the Act states that reasonable steps include both technical measures, such as access controls and multi-factor authentication, and organisational measures, such as policies and training. APP 11 also requires you to destroy or de-identify personal information once it is no longer needed.
The Notifiable Data Breaches scheme
If personal information you hold is lost or accessed without authorisation and serious harm is likely, the Notifiable Data Breaches scheme requires you to notify the OAIC and the affected individuals. A suspected breach must be assessed within 30 days. The obligation is the same whether the person involved sits in Sydney or Manila, which is why your incident plan should name your offshore team member and your Offshored account manager.
None of this prohibits offshoring. It sets the standard you have to meet, and our guide Is offshoring legal in Australia? covers the wider legal picture.
Sources: OAIC, APP guidelines chapter 8, cross-border disclosure of personal information; OAIC, APP guidelines chapter 11, security of personal information; OAIC, About the Notifiable Data Breaches scheme.